Hole was reportedly caused by older security updates to the web browser

Apr 28, 2009 10:36 GMT  ·  By

Mozilla has released a new update to its powerful web browser for Mac, PC and Linux, fixing a critical issue caused by one of the security fixes in Firefox 3.0.9. The Mozilla Foundation Security Advisory 2009-23 reveals that users of the HTML Validator add-on were particularly affected.

Titled “Crash in nsTextFrame::ClearTextRun(),” the vulnerability was announced yesterday and was listed as “Critical,” after being reported by Marc Gueury and Daniel Veditz. Mozilla claims to have patched the hole in the just-released Firefox 3.0.10. The Mozilla Foundation Security Advisory 2009-23 is available for your reading pleasure below.

Title: Crash in nsTextFrame::ClearTextRun()

Impact: Critical;

Announced: April 27, 2009; Reporter: Marc Gueury, Daniel Veditz; Products: Firefox;

Fixed in: Firefox 3.0.10;

Description

One of the security fixes in Firefox 3.0.9 introduced a regression that caused some users to experience frequent crashes. Users of the HTML Validator add-on were particularly affected, but other users also experienced this crash in some situations. In analyzing this crash, we discovered that it was due to memory corruption similar to cases that have been identified as security vulnerabilities in the past.

Starting with Firefox version 3.1 Beta 2, Mozilla's popular web browser is based on the Gecko 1.9.1 rendering platform, which has been under development at Mozilla for almost a year now. At the time, Mozilla described Gecko 1.9.1 as “an incremental release on the previous version with significant changes to improve web compatibility, performance, and ease of use.”

On the Mac side, Mozilla Firefox requires at least Mac OS X 10.4 and later on a Macintosh computer with an Intel x86 or PowerPC G3, G4, or G5 processor, 128 MB of RAM (Recommended: 256 MB RAM or greater) and some 200 MB hard drive space. Fans of the web browser who wish to keep their web browsing activities as safe as possible are encouraged to download the latest (stable) version of Firefox using the link below. Versions 3.5 Beta 4, and 2.0.0.20 are also available at the same address.

Download Mozilla Firefox for Mac (Free)